CVE-2012-0866
Summary
| CVE | CVE-2012-0866 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-18 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 8.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.0 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.1.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA49272 - Red Hat update for postgresql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-2418-1 postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| PostgreSQL: Documentation: 9.1: Release 9.1.3 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Support / Security / Advisories / / MDVSA-2012:092 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| openSUSE-SU-2012:1173-1: moderate: postgresql to 9.1.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support / Security / Advisories / / MDVSA-2012:026 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Advisory SA49273 - Red Hat update for postgresql and postgresql84 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL: Security Update 2012-02-27 released | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| PostgreSQL: Documentation: 8.4: Release 8.4.11 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Support / Security / Advisories / / MDVSA-2012:027 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| PostgreSQL: Documentation: 8.3: Release 8.3.18 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| PostgreSQL: Documentation: 9.0: Release 9.0.7 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.